Likely scam — do not engage
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
credential_theftFake mail delivery failure notice from obscure domain with a hidden tinyurl link.
- Sender uses obscure whitelabelwebserver.com domain with URIBL blacklist hit and no RDAP record.
- Fake bounce message reports undeliverable email to unrelated gmail address using future 2026 date.
- Tinyurl.com shortener hides final destination of primary link.
- Additional links to lifeandhealthbd.com from suspicious web hosting directory.
- Fails all authentication with SPF=none, DKIM=none, DMARC=none.
- Microsoft SCL=5 flags it as spam/junk.
Do not click any links or reply. Delete the email and report it as phishing to your provider.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 33The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 33.
- AI analyst flagged 90% phishing likelihood (credential_theft).ai_phishing_detected-45
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- Message contains a URL shortener — obscures the real destination.url_shortener_present-5
- AI analyst flagged 10% spam likelihood.ai_spam_detected-2
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
okno RDAP record found
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Links extracted from this email
3 shownEach link was scored against a host-level suspicion heuristic. Click Scan link to run our full URL scanner on the destination — it'll show our verdict alongside Google Safe Browsing, VirusTotal, URLhaus, and the others.
- tinyurl.comshortener/48nnu58wLink shortener host (tinyurl.com) — final destination is hiddenSuspicion15
- support.google.com/mail/answer/81126Host contains credential-harvest keywordsSuspicion10
- lifeandhealthbd.com/bangkok_hospital_bd/asset/the=Suspicion0
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedbdix-r.whitelabelwebserver.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured